Vulnerabilities/

Injection and Command Injection in devcert

Severity:
High

Description

A command injection vulnerability in the devcert module may lead to remote code execution when users of the module pass untrusted input to the certificateFor function.

Recommendation

Update the devcert package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
devcert
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing